PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Split-Tender Scam Exploits Retail Software Glitch

By Tom Nawrocki
September 25, 2025
in Analysts Coverage, Merchant
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
klarna debit card

A glitch in split-tender payment processing allowed a group of criminals based in Miami to steal more than $1.5 million, according to the Justice Department. The scheme exploited a flaw in a retailer’s specific payment processing software rather than a vulnerability anyone could easily use.

According to the DOJ, the men purchased expensive merchandise and split the cost between two debit cards, then returned the items in-store. While one refund was being issued to the first card, accomplices deliberately stalled the second refund by presenting incorrect cards or entering wrong PINs.

During the return, others monitored the first card’s account remotely and quickly withdraw or transferred the credited funds. The delay on the second card kept the first transaction open, resulting in repeated credits to the first card.

Incorrectly Coded Software

This is not how payment processing normally works, which suggests the criminals had found a flaw in a specific point-of-sale (POS) system.

“If the POS software was coded correctly, it would have processed the split-tender refund as two transactions,” said Don Apgar, Director of Merchant Payments at Javelin Strategy & Research. “So when the credit to the second card failed, it would only re-attempt that credit, not start over and re-credit the first card as well.”

Another key factor was their knowledge that the store offered instant refunds.

“While one crook was in the store playing the game, his accomplice was withdrawing funds from the first card after each credit was applied,” said Apgar. “Normally, refunds wouldn’t hit a debit account until the following day, but there are new technologies that enable real-time credits, such as Visa Direct. The crooks would have to know that this store was using newer payout rails so they could grab the erroneous credits in real time before they were reversed.”

Leaving Retailers Vulnerable

The retailers affected by the scheme were not named in the indictment—possibly to avoid drawing attention to vulnerabilities in the software. The indictment noted that the scheme was carried out at dozens of stores in various cities across the country.

“This is such an arcane scheme,” said Apgar. “It sounds like one of these guys had insider info on this glitch in the store’s POS software.”

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Fraud TacticsJustice DepartmentRetailerScamSplit-tender

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    ai financial

    Consumers Are Putting More Financial Decisions in AI’s Hands

    April 17, 2026
    cybersecurity frontier ai

    Cybersecurity Must Evolve as Frontier AI Fuels New Fraud Risks

    April 16, 2026
    isos thriving

    In Defiance of the Prognosticators, ISOs Are Thriving Again

    April 15, 2026
    agentic payments

    Beyond the Click: How Agentic Payments Are Redefining Global Financial Flow

    April 14, 2026
    instant payments fraud

    Instant, Irrevocable Payments Demand a Fraud Prevention Reboot

    April 13, 2026
    samsung p2p

    Making Zelle Work Better for Users—and Banks

    April 10, 2026
    fraud escalate

    As Fraud Escalates, Taking a Beat Becomes a Critical Defense

    April 9, 2026
    privacy open banking

    As Open Banking Fuels Interconnectivity, Privacy Matters More

    April 8, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result